Terms for IT/OT operations and security

Concise, directly linkable definitions for asset inventories, OT security, critical infrastructure, standards, and platform operations. Each entry stays visible, citable, and connected to sources.

  1. An IT security incident is an event in which the confidentiality, integrity, availability, or authenticity of IT or OT systems may be impacted.

    For regulated companies, clear reporting paths, contact points, situational information, and reliable asset and dependency data matter so that the response does not stall at taking stock.

  2. ITAM stands for IT asset management and describes the structured collection and maintenance of IT assets across their operational lifecycle.

    For security and operations, ITAM connects asset identity, technical state, accountability, data sources, and dependencies. This website focuses on operational visibility and a dependable picture of the IT estate.

  3. ITSM stands for IT service management and describes how IT services are governed through processes, roles, tools, and continuous improvement.

    Typical ITSM work covers incidents, service requests, changes, problems, and service levels. A current asset and dependency baseline makes that work faster and more dependable.

  4. KRITIS is the German abbreviation for critical infrastructure: facilities and services whose disruption would have a significant impact on society.

    For operators, KRITIS is not only a compliance term. In operations, critical services, facilities, IT/OT dependencies, suppliers, risks, and evidence must stay connected so supply and response remain resilient.

  5. LDAP is a protocol for accessing directory services; Active Directory Domain Services is Microsoft's directory service for network objects, users, computers, and resources.

    For asset and access context, directory services matter because they shape accounts, groups, devices, permissions, and authentication paths across many enterprise networks.

  6. MDM stands for mobile device management and describes central management of mobile devices and endpoints through enrollment, policies, and device configuration.

    In operations, MDM helps onboard devices securely and govern apps, updates, compliance state, and access requirements. It becomes more useful when MDM data is connected with inventory, identities, EDR, and ITSM.

  7. MSP stands for managed service provider: a company that continuously delivers IT, security, or operational services for customers.

    In operations, an MSP works across multiple customers, contracts, and tool stacks. Tenant separation, clear responsibilities, current asset data, traceable service evidence, and secure access paths are therefore central.

  8. NIS is the European legal framework for a higher level of cybersecurity in network and information systems.

    The NIS2 directive expands the scope and tightens governance, risk, and reporting requirements for many organizations.

  9. NIST is a US federal agency for standards, metrology, and technical guidance.

    In a cybersecurity context, NIST guidance such as the Cybersecurity Framework or NIST SP 800-82 for OT security is broadly referenced.

  10. OAuth is an authorization standard that lets an application obtain access to resources without disclosing user passwords to the application.

    OAuth works with access tokens and is often combined with OpenID Connect; OAuth authorizes access, while OIDC adds the identity layer for authentication.

  11. OIDC (OpenID Connect) is a standard that lets users sign in through an external identity provider instead of keeping a separate password for each application.

    OIDC builds on OAuth 2.0. An application redirects the sign-in to the identity provider, which confirms the identity and returns a token. User management stays central, for example in Microsoft Entra ID.

  12. OT covers hardware and software that monitor and control physical devices, plants, processes, or infrastructure.

    In OT environments, availability, process safety, real-time behavior, and controlled changes often weigh more heavily than in classic IT.

  13. OTAM stands for OT asset management and describes the structured collection and maintenance of assets that monitor or control physical processes.

    In addition to identity and technical state, OTAM accounts for firmware, topology, production role, long lifecycles, maintenance windows, and the distinct requirements for availability and process safety.

  14. OWASP is a non-profit organization that provides freely usable materials and projects to improve software and application security.

    The OWASP Operational Technology Top 10 project extends security risk coverage to industrial and OT-adjacent environments.

  15. RBAC controls permissions through roles: users are assigned roles, and roles bundle the permitted actions or access.

    The model reduces administrative effort in larger environments because permissions can be granted in line with tasks, responsibilities, and organizational units.

  16. A risk assessment evaluates threats, impacts, and protection needs so security measures are set based on risk rather than uniformly.

    IEC 62443-3-2 uses risk analysis to define the system under consideration, divide it into zones and conduits, and assign target security levels.

  17. RMM stands for remote monitoring and management and describes software that lets IT teams or MSPs monitor and manage systems, endpoints, and networks remotely.

    RMM provides important operational data about availability, patches, agents, hardware, software, and remote support. Reliable decisions need reconciliation with asset inventory, PSA, identities, EDR, MDM, and customer scope.

  18. SaaS stands for Software as a Service and describes cloud software consumed as a service without customers operating the underlying infrastructure themselves.

    In IT operations, SaaS services matter for cost control, identities, permissions, data flows, contract management, offboarding, and audit evidence.